{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:bcb5dc6468aa8860bf2b008384f0dc30e2671f493be419239493ce585c592345","slug":"controls-technology-lifecycle-capacity-review","url":"/assets/agent_workflow-controls-technology-lifecycle-capacity-review-6ce5195e.6755cc959b9b0926.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-technology-lifecycle-capacity-review","description":"Standing operator workflow for the quarterly solution-asset lifecycle review and the availability/capacity planning cycle, from asset reconciliation and end-of-support disposition through capacity monitoring, corrective planning, and prior-period target validation. Each quarterly run is a recurring workflow instance attached to the EXISTING technology-lifecycle-and-capacity-management Control item (UC-SDLC-12/13; frequency = quarterly; control_owner = the IT control owner) — the instance enriches that standing Control and its linked records, never a fresh duplicate; the governing COBIT 2019 / NIST 800-53 mapping rides on Control.framework. In scope: the in-scope solutions, applications, and supporting infrastructure components (the services they run are Process items) with named owners, and the services carrying agreed availability and capacity (SLA/SLO) targets. Out of scope: the projects that execute an approved replacement or upgrade (each tracked externally as its own project item) and live incident response for availability outages. Named deliverables: the reconciled solution-asset register and optimization actions, the ranked end-of-support exposure list and disposition, funded replacement/upgrade plans (Issue items) and compensating-control records (Control items) with signed risk acceptances (policy_exception Issues carrying exception_expiry_date, on treatment: accept Risks), the capacity/availability dashboard and corrective plans, and the validated prior-period target package. No upstream workflow feeds this cycle and there is no separate downstream workflow to hand off to — the still-open replacement/upgrade plans, capacity corrective plans, and risk-acceptance expiries (their existing Issue and Risk items, linked to the anchor Control) carry forward as explicit inputs to the next quarterly run of this same workflow.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-technology-lifecycle-capacity-review","capabilities":[],"controls":["UC-SDLC-12","UC-SDLC-13"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:bcb5dc6468aa8860bf2b008384f0dc30e2671f493be419239493ce585c592345","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-technology-lifecycle-capacity-review","standards":["cobit-2019","nist-800-53"],"teams":["it"]},"id":"wf:C64","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC64","slug":"controls-technology-lifecycle-capacity-review","sourceIds":["cobit-2019","nist-800-53"],"sourceUrl":null,"title":"Technology Lifecycle & Capacity Review","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b07004b01c26b180943b890aecdc016338f3537705b062696c61c5cd1b9a040","properties":{},"sourceDetailPath":"/data/v1/records/wf-c64-5695dd2f.json","sourceId":"wf:C64","targetDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","targetId":"uc:UC-SDLC-12","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab356e88c1235ff26dfdb5b4d6f72c3c740004a126e38740f06318e22ff1fc32","properties":{},"sourceDetailPath":"/data/v1/records/wf-c64-5695dd2f.json","sourceId":"wf:C64","targetDetailPath":"/data/v1/records/uc-uc-sdlc-13-ae800997.json","targetId":"uc:UC-SDLC-13","type":"operates"}],"schemaVersion":1}
